Executive brief
ash_cloak is an Elixir library that encrypts sensitive data fields in web applications. When a field is encrypted without explicitly marking it as sensitive, the plaintext value leaks into logs, error messages, and crash reports where developers and operations staff can see it, defeating the encryption's purpose.
Technical details
The vulnerability exists in AshCloak.Transformers.SetUpEncryption, which generates action arguments to carry plaintext values into the encryption change. When a cloaked attribute lacks the sensitive?: true flag, the generated argument inherits this configuration and is not marked sensitive, causing Ash to not redact it in inspect(changeset), Ash.Error.Invalid messages, validation errors, telemetry, :sys dumps, and error-tracker payloads. An attacker with access to logs, error trackers, crash reports, or the ability to trigger validation errors can recover the plaintext of encrypted fields. The encrypted attribute and decrypt calculation are hardcoded as sensitive, but this protection does not extend to the intermediate plaintext argument. Affected versions are 0.1.0 through 0.3.x; upgrade to 0.4.0 or later.
Affected products
- ash-project ash_cloak 0.1.0 before 0.4.0
Timeline
- 2026-08-30: disclosed